🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Fasthosts

United Kingdom · IaaS/PaaS · https://www.fasthosts.co.uk

Sovereignty score33.8%
Global (unweighted)33.5%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty36.6SEAL-1
SOV-2 Legal & Jurisdictional Sovereignty29.3SEAL-1
SOV-3 Data & AI Sovereignty35.0SEAL-0
SOV-4 Operational Sovereignty33.5SEAL-1
SOV-5 Supply Chain Sovereignty36.0SEAL-1
SOV-6 Technology Sovereignty30.0SEAL-2
SOV-7 Security & Compliance Sovereignty36.0SEAL-1
SOV-8 Environmental Sustainability31.4SEAL-0

SOV-1 · Strategic Sovereignty 36.6% · SEAL-1 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control2. Mostly outside the EU42/125SEAL-1highno eu_entity (UK third-country incorporation/operations), but a genuine EU operational nexus via the German parent United Internet AG / IONOS (which engineers the CloudNX platform) -> SOV-1.1 opt2 'mostly outside EU' (seal 1); contracting entity, data centre and staff sit in the UK. (src: https://www.ionos.co.uk/newsroom/news/ionos-and-fasthosts-achieve-tier-iv-certification-for-worcester-data-centre/)
SOV-1.2Change of control risk4. Unlikely takeover/transfer to non-EU sovereign entity94/125SEAL-4mediumOwned since 2006 by German United Internet AG (an EU/EEA group), so a transfer to a non-EU sovereign entity is unlikely; main residual risk is the UK operating base. (SOV-1.2 all-seal-4, choice kept.)
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2lowNo formal customer governance bodies; roadmap influence limited to voice-of-the-customer channels for a commercial mass-market host -> SOV-1.3 opt2.
SOV-1.4Financial independence from non-EU capital4. Majority of funding is EU-based94/125SEAL-4mediumBacked by United Internet AG, a publicly listed German (EU) group, so the majority of funding is EU-based. (SOV-1.4 all-seal-4, choice kept.)
SOV-1.5EU economic contribution2. Some31/125SEAL-4mediumEconomic contribution (jobs, data centre, taxes) is concentrated in the UK third country; the EU benefits only indirectly via the German parent. (SOV-1.5 all-seal-4, choice kept.)
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4mediumNo evidence of participation in EU strategic programs (Gaia-X, IPCEI-CIS); UK commercial host with no EU strategic engagement. (SOV-1.6 all-seal-4, choice kept.)
SOV-1.7Alignment with EU industrial strategies1. No evidence exists0/125SEAL-4mediumNo action plan aligning Fasthosts with EU industrial strategies; positions itself as a UK web host. (SOV-1.7 all-seal-4, choice kept.)
SOV-1.8Resilience to cut-off3. Can continue temporarily per contractual agreement63/125SEAL-2lowno own_stack in EU-jurisdiction terms: owns its own UK Tier IV data centre and CloudNX platform (EU-parent maintained) so it could continue temporarily, but real non-EU dependencies (chips/OS/hypervisor) and UK base mean no full autonomy -> SOV-1.8 opt3 (seal 2).

SOV-2 · Legal & Jurisdictional Sovereignty 29.3% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction1. Non-EU only0/167SEAL-1highno EU jurisdiction: contracts governed by the law of England and Wales (UK, non-EU); not exclusively EU law -> SOV-2.1 opt1 (seal 1, ceiling). (src: https://www.ionos.co.uk/newsroom/news/ionos-and-fasthosts-achieve-tier-iv-certification-for-worcester-data-centre/)
SOV-2.2Extraterritorial laws exposure2. Mitigation clauses, exposure remains42/167SEAL-1mediumno immunity (UK Investigatory Powers Act exposure; no SecNumCloud/EUCS-High; UK operational nexus); GDPR adequacy + contract clauses mitigate but exposure remains -> SOV-2.2 opt2 (seal 1).
SOV-2.3Data access pathways for non-EU authorities2. Can compel access without notification, specific cases42/167SEAL-1mediumno immunity: under the UK Investigatory Powers Act (technical capability/national security notices) authorities can compel access in specific cases, possibly with non-disclosure; no published always-reject policy -> SOV-2.3 opt2 (seal 1, ceiling).
SOV-2.4Export control restrictions2. Restrictions towards EU citizens or international orgs42/167SEAL-1lowno eu_exclusive: as a non-EU (UK) provider the offer is not specifically shielded from non-EU export controls affecting EU citizens/orgs, and UK-billed revenue is not >50% in the EU; no EU-MS-specific restriction identified -> SOV-2.4 opt2 (seal 1). Normalised with the UK cluster.
SOV-2.5Origin of IP3. Mixed within/outside the EU84/167SEAL-4lowCore CloudNX/IONOS software IP is German (EU) but OS, hypervisor and hardware IP are largely non-EU -> mixed within/outside-EU IP origin, SOV-2.5 opt3. (all-seal-4 factor.)
SOV-2.6IP holder jurisdiction3. Mixed law, some EU84/167SEAL-3lowIP held across the United Internet group (German/EU) and third-party vendors under non-EU law (US software licences) -> mixed law with some EU, SOV-2.6 opt3 (seal 3).

SOV-3 · Data & AI Sovereignty 35.0% · SEAL-0 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys2. Primarily provider, not exclusively50/200SEAL-1lowStandard IaaS/hosting: encryption is primarily provider-managed, no advertised customer-exclusive HYOK/BYOK preventing provider access -> SOV-3.1 opt2 (seal 1).
SOV-3.2Transparent data flows & access logs2. Basic incomplete logs50/200SEAL-1lowBasic control-panel access/activity logging only; no comprehensive real-time independently auditable data-flow logs -> SOV-3.2 opt2 (seal 1).
SOV-3.3Secure deletion & proof of erasure2. Manual confirmation only50/200SEAL-1lowDeletion on account termination with manual confirmation; no published cryptographic proof-of-erasure -> SOV-3.3 opt2 (seal 1).
SOV-3.4Data location strictly in EU/EEA2. Partly EU, significant third-country reliance50/200SEAL-0highno eu_exclusive: customer data is hosted in Fasthosts' UK (Worcester) data centre, a third country, not EU/EEA, with no EU-exclusivity guarantee -> third-country hosting with safeguards, SOV-3.4 opt2 (seal 0), per key anchor 'no EU-exclusivity guarantee -> SEAL-0'. Normalised with the UK-only cluster members. (src: https://www.ionos.co.uk/newsroom/news/ionos-and-fasthosts-achieve-tier-iv-certification-for-worcester-data-centre/)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3lowNo in-scope AI service: Fasthosts has no significant in-house AI offering, so there is no foreign-AI/black-box model dependency to penalise -> key judgment-call #2 maps 'no in-scope AI service' to opt4 (seal 3). Normalised with the no-AI cluster members (Brightbox, Pulsant).

SOV-4 · Operational Sovereignty 33.5% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumStandard documented data-export/backup methods with common OS/stacks (Linux, Windows, standard VMs) -> documented portability, SOV-4.1 opt3 (seal 4).
SOV-4.2Ability to operate without foreign dependencies2. Ops partially sourced within EU42/167SEAL-1mediumno eu_ops: critical operations run from the UK third country (platform engineered by the German parent), not a fully EU-based operational team -> SOV-4.2 opt2 (seal 1).
SOV-4.3Skill availability in the EU2. Mixed, majority outside EU42/167SEAL-1mediumno eu_ops: engineering/operations staff concentrated in the UK (non-EU); from an EU perspective the skill base is majority outside the EU/EEA -> SOV-4.3 opt2 (seal 1).
SOV-4.4Support channels2. Mixed, majority outside EU42/167SEAL-2mediumno eu_ops: support delivered by UK-based teams (Gloucester, third country), so majority of support staff sit outside the EU/EEA -> SOV-4.4 opt2 (seal 2).
SOV-4.5Documentation & knowledge transfer2. EU optional, not enforced42/167SEAL-2lowDocumentation/knowledge bases are English and UK-hosted with no enforced EU-only handling; EU residency optional at best -> SOV-4.5 opt2 (seal 2).
SOV-4.6Subcontractor & supplier jurisdiction3. Continue temporarily per contractual agreement84/167SEAL-3lowOwn Tier IV data centre plus German-parent supply relationships mean the service could continue temporarily under contract if a single non-EU supplier failed, though the supplier base is not EU-confined -> SOV-4.6 opt3 (seal 3).

SOV-5 · Supply Chain Sovereignty 36.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowHardware components (HPE/Juniper) sourced from non-EU vendors with only partial public provenance disclosure -> SOV-5.1 opt2 (seal 1).
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1lowServers and network gear manufactured by foreign OEMs (HPE, Juniper) outside the EU, partial disclosure -> SOV-5.2 opt2 (seal 1).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/BIOS and embedded code in commodity servers/network kit come from non-EU OEMs with limited provenance disclosure -> SOV-5.3 opt2. (all-seal-4 factor, choice kept.)
SOV-5.4Origin of software3. Core/essential parts maintained by EU teams72/143SEAL-3lowno foreign_core for the control plane: the CloudNX control-plane software is developed/maintained by the German (EU) IONOS group, so core essential software is EU-maintained while OS/hypervisor layers remain foreign -> SOV-5.4 opt3 (seal 3).
SOV-5.5Software build/release jurisdiction3. Non-EU control, EU execution72/143SEAL-3lowPlatform software built/released under EU control by the German parent while underlying components remain non-EU -> non-EU control with substantial EU execution, SOV-5.5 opt3 (seal 3).
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2lowA few non-EU vendors in critical layers (chips, OS, hypervisor, network hardware), but documented standard products rather than a single undocumented dependency -> SOV-5.6 opt3 (seal 2).
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowSome suppliers and the ISO 27001/Tier IV facility are auditable, but the full upstream hardware/software chain is not broadly customer-auditable -> SOV-5.7 opt2 (seal 1).

SOV-6 · Technology Sovereignty 30.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces3. Mixed (partial openness)100/200SEAL-2lowCloudNX exposes APIs and supports standard OS images/tooling -> partial openness, not open-by-default or fully portable, SOV-6.1 opt3 (seal 2).
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2lowCommon open standards (HTTP, TLS, standard VM/storage formats, DNS) used for core services, but no published policy mandating open standards across all services -> SOV-6.2 opt3 (seal 2).
SOV-6.3Open source availability1. Fully closed-source, vendor-controlled0/200SEAL-2lowThe CloudNX control plane and management software are proprietary and vendor-controlled; not an open-source-centric provider -> SOV-6.3 opt1 (seal 2).
SOV-6.4Service architecture transparency2. Insight accessible during audits50/200SEAL-2lowArchitecture detail shared mainly under audit/commercial engagement; only marketing-level public insight -> SOV-6.4 opt2 (seal 2).
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowNo dedicated/in-scope HPC service -> treated as no-in-scope-HPC, SOV-6.5 opt2 (seal 3) per key rather than imported black-box.

SOV-7 · Security & Compliance Sovereignty 36.0% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)1. EAL0 / none0/143SEAL-1lowno qualifying cert: holds ISO 27001 and Uptime Tier IV but no Common Criteria EAL, SecNumCloud or EUCS evaluation -> effectively EAL0/none, SOV-7.1 opt1 (seal 1). (src: https://www.ionos.co.uk/newsroom/news/ionos-and-fasthosts-achieve-tier-iv-certification-for-worcester-data-centre/)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)3. Moderate compliance72/143SEAL-4mediumComplies with (UK) GDPR/DPA and holds ISO 27001 -> moderate adherence; no evidence of full independently audited NIS2/DORA, SOV-7.2 opt3. (all-seal-4 factor.)
SOV-7.3EU-based SOC & incident handling3. Primary SOC in EU, escalations non-EU72/143SEAL-1lowSecurity operations run by UK-based teams (third country) with no ENISA/CSIRT integration; closest to a primary SOC outside the EU -> SOV-7.3 opt3 (seal 1).
SOV-7.4Control over security monitoring/logging2. Customers receive periodic reports36/143SEAL-1lowControl-panel monitoring and periodic reporting rather than full direct access to immutable EU-stored security logs -> SOV-7.4 opt2 (seal 1).
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumIncident disclosure follows GDPR/UK breach-notification duties -> moderate NIS2/GDPR-aligned disclosure without real-time CSIRT sharing, SOV-7.5 opt3 (seal 2).
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowOperator of its own data centre and platform -> moderate maintenance autonomy with scheduled/notified windows and testing, SOV-7.6 opt3 (seal 4).
SOV-7.7Auditability2. Limited independent access36/143SEAL-1lowno audit_rights: independent audit limited to certification bodies (ISO 27001, Uptime Institute), not open audit by the contracting authority or any independent EU body -> SOV-7.7 opt2 (seal 1, ceiling).

SOV-8 · Environmental Sustainability 31.4% · SEAL-0 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4mediumModern Tier IV Worcester data centre (£21M, opened 2022) designed for high efficiency with onsite solar and a sustainability roadmap; PUE <1.5 + roadmap plausible -> SOV-8.1 opt3 (seal 4). (src: https://www.ionos.co.uk/newsroom/news/ionos-and-fasthosts-achieve-tier-iv-certification-for-worcester-data-centre/)
SOV-8.2Hardware reuse & recycling2. Basic circular practices63/250SEAL-0lowSustainability messaging (carbon-compensated construction, modern facility) indicates basic circular practices, but no documented hardware reuse/recycling program -> SOV-8.2 opt2 (seal 0).
SOV-8.3Environmental impact reporting2. Basic reporting63/250SEAL-1lowSome environmental claims published (renewable energy, carbon compensation) but no comprehensive methodology-based annual environmental report for Fasthosts itself -> SOV-8.3 opt2 (seal 1).
SOV-8.4Energy supplies2. Only EU energy supplies63/250SEAL-4mediumWorcester data centre reported to run on 100% renewable energy sourced in the UK (local, non-EU, onsite solar covering up to 10%); traceable single-region renewable supply, SOV-8.4 opt2. (all-seal-4 factor, choice kept.) (src: https://www.ionos.co.uk/newsroom/news/ionos-and-fasthosts-achieve-tier-iv-certification-for-worcester-data-centre/)